Cookie Policy
Last updated: 27 September 2026
1. What Are Cookies
Cookies are small text files stored on your device when you visit our website. They help us provide you with a better experience by remembering your preferences, keeping you logged in, and enabling certain features to work properly.
2. Types of Cookies We Use
Essential Cookies
Required for the website to function. Cannot be disabled.
- __Secure-next-auth.session-token: keeps you signed in and authenticates your requests. Set when you sign in.
- __Host-next-auth.csrf-token: protects the sign-in and sign-out forms against cross-site request forgery.
- __Secure-next-auth.callback-url: remembers which page to return you to after signing in.
- nextauth.message (browser storage, not a cookie): keeps your sign-in state in step across open tabs.
Functional Cookies
Remember choices you make on the site.
- cobalt:scroll:… (browser storage for this tab only, not a cookie): remembers how far down a page you were, so Back returns you there.
- cobalt-cookie-consent (browser storage, not a cookie): remembers the choice you made in the banner.
- cobalt_currency: remembers whether you chose EUR or USD, so prices show and payments are charged in it. Set only when you use the switch; cleared when you close the browser.
Analytics Cookies
Help us understand how visitors interact with our website.
- Page views and navigation patterns
- Feature usage and time spent on pages
3. Managing Cookies
When you first visit Cobalt, our cookie banner lets you choose "Essential only" or "Accept all" to enable Analytics cookies. You can change this choice at any time using the button below, which re-opens the preferences banner. You can also control cookies through your browser settings. Note that disabling essential cookies may impact the functionality of our service and prevent you from logging in.
How to Manage Cookies in Popular Browsers
- Chrome: Settings → Privacy and Security → Cookies
- Firefox: Options → Privacy & Security → Cookies
- Safari: Preferences → Privacy → Manage Website Data
- Edge: Settings → Privacy, Search, and Services → Cookies
4. Third-Party Cookies
We may use third-party services that set their own cookies:
- Our card-payment processor may set cookies on its own 3-D Secure pages during a card payment. It sets none while you are only browsing this site.
- PostHog, our product-analytics provider, for usage statistics. It sets a
ph_…_posthogcookie and a matching browser-storage entry, plus aph_idententry that links the statistics to your account while you are signed in — all only after you choose "Accept all".
5. Cookie Retention
Session cookies are deleted when you close your browser.
Persistent cookies remain on your device for up to 1 year or until you delete them manually. Authentication cookies expire after 30 days of inactivity.
6. Updates to This Policy
We may update this Cookie Policy from time to time. Changes are posted on this page with an updated revision date. An update does not change the choice you already made, and carrying on browsing is not treated as agreement to anything: analytics cookies run only while your saved choice is "Accept all", and you can withdraw that at any time with the Manage Cookies button above.
Questions about cookies? Write to support@cobalt.boutique.